---
id: CVE-2025-15602
title: >-
  Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to
  account privileges that are insufficiently protected against mass assignment
summary: >-
  Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to
  account privileges that are insufficiently protected against mass assignment.
  An authenticated, low-privileged user can craft a malicious API request to
  modify…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-915
vendor: snipeitapp
product: snipe-it
affected:
  - snipe-it < 8.3.7
patched:
  - snipe-it 8.3.7
published: '2026-03-06'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:50.573'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15602'
references:
  - url: 'https://github.com/grokability/snipe-it/releases/tag/v8.3.7'
    label: disclosure@vulncheck.com
  - url: 'https://snipeitapp.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/snipe-it-mass-assignment-vulnerability-leading-to-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-09T15:12:04.582716Z'
epss: 0.00467
epssPercentile: 0.3844
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Nxvh1337/CVE-2025-15602-PoC'
  checkedAt: '2026-10-08T16:52:49.761Z'
exploitAvailable: true
ingestedAt: '2026-10-08T16:52:14.674Z'
---

## Overview

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.

## Affected

- `snipe-it < 8.3.7`

## Remediation

Upgrade past the affected range:

- `snipe-it 8.3.7`
